Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
NoInputSignal
on April 16, 2020
|
parent
|
context
|
favorite
| on:
Auth0 JWT Auth Bypass: Case-Sensitive Blacklisting...
I think this points out that the semantics of trusting the header (which is still a part of the message) at all is flawed and leads to implementations getting it wrong and leaving gaps for attackers to exploit.
Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: